{"id":148168,"date":"2026-04-07T11:19:51","date_gmt":"2026-04-07T19:19:51","guid":{"rendered":"https:\/\/xira.com\/p\/2026\/04\/07\/jones-day-gets-hacked-while-fbi-busy-planning-kash-patels-next-vacation\/"},"modified":"2026-04-07T11:19:51","modified_gmt":"2026-04-07T19:19:51","slug":"jones-day-gets-hacked-while-fbi-busy-planning-kash-patels-next-vacation","status":"publish","type":"post","link":"https:\/\/xira.com\/p\/2026\/04\/07\/jones-day-gets-hacked-while-fbi-busy-planning-kash-patels-next-vacation\/","title":{"rendered":"Jones Day Gets Hacked While FBI Busy Planning Kash Patel\u2019s Next Vacation"},"content":{"rendered":"<p>Jones Day acknowledged that an \u201cunauthorised third party accessed a limited number of dated files for 10 clients\u201d and that all affected clients have been notified. The attackers claimed they focused on the head of the firm\u2019s Federal Circuit team, supposedly referring to Greg Castanias. Jones Day declined to identify the clients or the specific files involved, displaying the kind of attention to secrecy that could\u2019ve avoided this whole problem to begin with.<\/p>\n<p>The attack has been <a href=\"https:\/\/databreaches.net\/2026\/04\/06\/jones-day-confirms-limited-breach-after-phishing-attack-by-silent-ransom-group\/\" rel=\"nofollow noopener\" target=\"_blank\">attributed to the Silent Ransom Group<\/a>, also known as Luna Moth, Chatty Spider, and UNC3753 \u2014 all excellent garage band names for anyone in the market. According to an <a href=\"https:\/\/www.fbi.gov\/file-repository\/cyber-alerts\/silent-ransom-group-targeting-law-firms-052325.pdf\/view\" rel=\"nofollow noopener\" target=\"_blank\">FBI alert last May<\/a>, SRG has been targeting law firms specifically since 2023. But that was before the federal law enforcement agency <a href=\"https:\/\/www.msn.com\/en-us\/news\/insight\/fired-fbi-agents-allege-political-purge\/gm-GM827F9FFF?gemSnapshotKey=GM827F9FFF-snapshot-3&amp;ocid=hpmsn\" rel=\"nofollow noopener\" target=\"_blank\">embarked on a half-baked loyalty purge<\/a> and <a href=\"https:\/\/www.theguardian.com\/us-news\/2025\/oct\/09\/fbi-agents-reassigned-ice-immigration\" rel=\"nofollow noopener\" target=\"_blank\">reassigned the remaining agents to rounding up roofers<\/a> and <a href=\"https:\/\/abovethelaw.com\/2025\/05\/kash-patel-says-hes-prioritizing-social-media-mocking-trump-over-child-sex-predators-fentanyl-traffickers-terrorists\/\" rel=\"nofollow noopener\" target=\"_blank\">threatening people for making fun of Trump on Instagram<\/a>. Today, the FBI exists mostly as a luxury travel agent for <a href=\"https:\/\/www.npr.org\/2026\/02\/25\/nx-s1-5724942\/fbi-directors-leadership-questioned-after-partying-with-the-us-mens-hockey-team\" rel=\"nofollow noopener\" target=\"_blank\">Kash Patel to slam beers with hockey players<\/a>. <\/p>\n<p>As a bulwark against cybercrime, the FBI is essentially an offensive lineman who immediately turns around and yells \u201cincoming!\u201d at the quarterback.<\/p>\n<p>SRG\u2019s M.O. is social engineering \u2014 phishing emails and phone calls impersonating IT staff \u2014 rather than sophisticated zero-day exploits. They don\u2019t even really employ malware. They just convince someone to give them remote access and then walk out with the data using off-the-shelf file transfer tools.<\/p>\n<p>The group <a href=\"https:\/\/www.legalcheek.com\/2026\/04\/jones-day-confirms-cyber-attack-after-hackers-access-client-files\/\" rel=\"nofollow noopener\" target=\"_blank\">published a file directory and screenshots<\/a> of what appear to be negotiation chats between SRG and Jones Day representatives. According to reporting, the hackers demanded $13 million to keep quiet about the breach. When Jones Day didn\u2019t immediately open the checkbook, the negotiations broke down. The group\u2019s final message \u2014 from a negotiator identifying themselves as \u201cAmmiel Olsen\u201d \u2014 warned that they would publish all the data, contact every employee and client, and resume attacks on the firm. <\/p>\n<p>This is not Jones Day\u2019s first time at the breach rodeo. The firm was among several companies caught up in a 2021 hack of the Accellion file transfer software, which resulted in client data \u2014 including prescription drug records \u2014 being dumped online. So when we talk about whether firms are successfully staying ahead of the cyber threat, here\u2019s a firm dealing with its second major incident in five years.<\/p>\n<p>The FBI\u2019s old warning about SRG noted that the group targets law firms \u201clikely due to the highly sensitive nature of legal industry data.\u201d Well, <em>that<\/em> and the fact that they know a soft target when they see one. While everyone keeps hyping up AI well beyond its actual capabilities, cybersecurity remains a potentially expensive exposure. <\/p>\n<p>It\u2019s unclear if SRG followed through on its threat to renew attacks. But, because it\u2019s 2026, their warning message to the firm threw in that the reputational damage would sting even more \u201cespecially after being exposed in the Epstein files about your ties with child predators.\u201d<\/p>\n<p>I don\u2019t know. It kind of feels like being exposed in the Epstein files takes the sting out of anything else a hacking group could throw.<\/p>\n<hr>\n<p><strong><em><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-443318\" src=\"https:\/\/i0.wp.com\/abovethelaw.com\/wp-content\/uploads\/sites\/4\/2016\/11\/Headshot-300x200.jpg?resize=192%2C128&#038;ssl=1\" alt=\"Headshot\" width=\"192\" height=\"128\" title=\"\"><a href=\"http:\/\/abovethelaw.com\/author\/joe-patrice\/\" target=\"_blank\" rel=\"noopener nofollow\">Joe Patrice<\/a>\u00a0is a senior editor at Above the Law and co-host of <a href=\"http:\/\/legaltalknetwork.com\/podcasts\/thinking-like-a-lawyer\/\" target=\"_blank\" rel=\"noopener nofollow\">Thinking Like A Lawyer<\/a>. Feel free to\u00a0<a href=\"mailto:joepatrice@abovethelaw.com\">email<\/a> any tips, questions, or comments. Follow him on\u00a0<a href=\"https:\/\/twitter.com\/josephpatrice\" target=\"_blank\" rel=\"noopener nofollow\">Twitter<\/a>\u00a0or <a href=\"https:\/\/bsky.app\/profile\/joepatrice.bsky.social\" rel=\"noopener nofollow\" target=\"_blank\">Bluesky<\/a> if you\u2019re interested in law, politics, and a healthy dose of college sports news. Joe also serves as a <a href=\"https:\/\/www.rpnexecsearch.com\/josephpatrice\" target=\"_blank\" rel=\"noopener nofollow\">Managing Director at RPN Executive Search<\/a>.<\/em><\/strong><\/p>\n<p>The post <a href=\"https:\/\/abovethelaw.com\/2026\/04\/jones-day-gets-hacked-while-fbi-busy-planning-kash-patels-next-vacation\/\" rel=\"nofollow noopener\" target=\"_blank\">Jones Day Gets Hacked While FBI Busy Planning Kash Patel\u2019s Next Vacation<\/a> appeared first on <a href=\"https:\/\/abovethelaw.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Above the Law<\/a>.<\/p>\n<figure class=\"post-single__featured-image post-single__featured-image--medium alignright\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"200\" src=\"https:\/\/i0.wp.com\/abovethelaw.com\/wp-content\/uploads\/sites\/4\/2025\/11\/GettyImages-1599973349-300x200.jpg?resize=300%2C200&#038;ssl=1\" class=\"attachment-medium size-medium wp-post-image\" alt=\"\" title=\"\"><\/figure>\n<p>Jones Day acknowledged that an \u201cunauthorised third party accessed a limited number of dated files for 10 clients\u201d and that all affected clients have been notified. The attackers claimed they focused on the head of the firm\u2019s Federal Circuit team, supposedly referring to Greg Castanias. Jones Day declined to identify the clients or the specific files involved, displaying the kind of attention to secrecy that could\u2019ve avoided this whole problem to begin with.<\/p>\n<p>The attack has been <a href=\"https:\/\/databreaches.net\/2026\/04\/06\/jones-day-confirms-limited-breach-after-phishing-attack-by-silent-ransom-group\/\" rel=\"nofollow noopener\" target=\"_blank\">attributed to the Silent Ransom Group<\/a>, also known as Luna Moth, Chatty Spider, and UNC3753 \u2014 all excellent garage band names for anyone in the market. According to an <a href=\"https:\/\/www.fbi.gov\/file-repository\/cyber-alerts\/silent-ransom-group-targeting-law-firms-052325.pdf\/view\" rel=\"nofollow noopener\" target=\"_blank\">FBI alert last May<\/a>, SRG has been targeting law firms specifically since 2023. But that was before the federal law enforcement agency <a href=\"https:\/\/www.msn.com\/en-us\/news\/insight\/fired-fbi-agents-allege-political-purge\/gm-GM827F9FFF?gemSnapshotKey=GM827F9FFF-snapshot-3&amp;ocid=hpmsn\" rel=\"nofollow noopener\" target=\"_blank\">embarked on a half-baked loyalty purge<\/a> and <a href=\"https:\/\/www.theguardian.com\/us-news\/2025\/oct\/09\/fbi-agents-reassigned-ice-immigration\" rel=\"nofollow noopener\" target=\"_blank\">reassigned the remaining agents to rounding up roofers<\/a> and <a href=\"https:\/\/abovethelaw.com\/2025\/05\/kash-patel-says-hes-prioritizing-social-media-mocking-trump-over-child-sex-predators-fentanyl-traffickers-terrorists\/\" rel=\"nofollow noopener\" target=\"_blank\">threatening people for making fun of Trump on Instagram<\/a>. Today, the FBI exists mostly as a luxury travel agent for <a href=\"https:\/\/www.npr.org\/2026\/02\/25\/nx-s1-5724942\/fbi-directors-leadership-questioned-after-partying-with-the-us-mens-hockey-team\" rel=\"nofollow noopener\" target=\"_blank\">Kash Patel to slam beers with hockey players<\/a>. <\/p>\n<p>As a bulwark against cybercrime, the FBI is essentially an offensive lineman who immediately turns around and yells \u201cincoming!\u201d at the quarterback.<\/p>\n<p>SRG\u2019s M.O. is social engineering \u2014 phishing emails and phone calls impersonating IT staff \u2014 rather than sophisticated zero-day exploits. They don\u2019t even really employ malware. They just convince someone to give them remote access and then walk out with the data using off-the-shelf file transfer tools.<\/p>\n<p>The group <a href=\"https:\/\/www.legalcheek.com\/2026\/04\/jones-day-confirms-cyber-attack-after-hackers-access-client-files\/\" rel=\"nofollow noopener\" target=\"_blank\">published a file directory and screenshots<\/a> of what appear to be negotiation chats between SRG and Jones Day representatives. According to reporting, the hackers demanded $13 million to keep quiet about the breach. When Jones Day didn\u2019t immediately open the checkbook, the negotiations broke down. The group\u2019s final message \u2014 from a negotiator identifying themselves as \u201cAmmiel Olsen\u201d \u2014 warned that they would publish all the data, contact every employee and client, and resume attacks on the firm. <\/p>\n<p>This is not Jones Day\u2019s first time at the breach rodeo. The firm was among several companies caught up in a 2021 hack of the Accellion file transfer software, which resulted in client data \u2014 including prescription drug records \u2014 being dumped online. So when we talk about whether firms are successfully staying ahead of the cyber threat, here\u2019s a firm dealing with its second major incident in five years.<\/p>\n<p>The FBI\u2019s old warning about SRG noted that the group targets law firms \u201clikely due to the highly sensitive nature of legal industry data.\u201d Well, <em>that<\/em> and the fact that they know a soft target when they see one. While everyone keeps hyping up AI well beyond its actual capabilities, cybersecurity remains a potentially expensive exposure. <\/p>\n<p>It\u2019s unclear if SRG followed through on its threat to renew attacks. But, because it\u2019s 2026, their warning message to the firm threw in that the reputational damage would sting even more \u201cespecially after being exposed in the Epstein files about your ties with child predators.\u201d<\/p>\n<p>I don\u2019t know. It kind of feels like being exposed in the Epstein files takes the sting out of anything else a hacking group could throw.<\/p>\n<hr \/>\n<p><strong><em><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-443318\" src=\"https:\/\/i0.wp.com\/abovethelaw.com\/wp-content\/uploads\/sites\/4\/2016\/11\/Headshot-300x200.jpg?resize=192%2C128&#038;ssl=1\" alt=\"Headshot\" width=\"192\" height=\"128\" title=\"\"><a href=\"http:\/\/abovethelaw.com\/author\/joe-patrice\/\" target=\"_blank\" rel=\"noopener nofollow\">Joe Patrice<\/a>\u00a0is a senior editor at Above the Law and co-host of <a href=\"http:\/\/legaltalknetwork.com\/podcasts\/thinking-like-a-lawyer\/\" target=\"_blank\" rel=\"noopener nofollow\">Thinking Like A Lawyer<\/a>. Feel free to\u00a0<a href=\"https:\/\/abovethelaw.com\/cdn-cgi\/l\/email-protection#d3b9bcb6a3b2a7a1bab0b693b2b1bca5b6a7bbb6bfb2a4fdb0bcbe\" rel=\"nofollow noopener\" target=\"_blank\">email<\/a> any tips, questions, or comments. Follow him on\u00a0<a href=\"https:\/\/twitter.com\/josephpatrice\" target=\"_blank\" rel=\"noopener nofollow\">Twitter<\/a>\u00a0or <a href=\"https:\/\/bsky.app\/profile\/joepatrice.bsky.social\" rel=\"noopener nofollow\" target=\"_blank\">Bluesky<\/a> if you\u2019re interested in law, politics, and a healthy dose of college sports news. Joe also serves as a <a href=\"https:\/\/www.rpnexecsearch.com\/josephpatrice\" target=\"_blank\" rel=\"noopener nofollow\">Managing Director at RPN Executive Search<\/a>.<\/em><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Jones Day acknowledged that an \u201cunauthorised third party accessed a limited number of dated files for 10 clients\u201d and that all affected clients have been notified. The attackers claimed they focused on the head of the firm\u2019s Federal Circuit team, supposedly referring to Greg Castanias. Jones Day declined to identify the clients or the specific [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":148159,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[16],"tags":[],"class_list":["post-148168","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-above_the_law"],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/xira.com\/p\/wp-content\/uploads\/2026\/04\/Headshot-300x200-HpRMs8.jpg?fit=300%2C200&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts\/148168","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/comments?post=148168"}],"version-history":[{"count":0,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts\/148168\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/media\/148159"}],"wp:attachment":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/media?parent=148168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/categories?post=148168"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/tags?post=148168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}